PT-2026-32928 · Docmost · Docmost

0Xmrma

·

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-33146

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Docmost versions 0.70.0 through 0.70.2
Description An authorization bypass in this open-source collaborative wiki and documentation software exposes restricted child page titles and text snippets. This occurs through the public search endpoint ''/api/search/share-search'' for publicly shared content, allowing unauthenticated users to enumerate and retrieve content that should be hidden from public share viewers, resulting in a confidentiality breach.
Recommendations Update to version 0.70.3.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33146

Affected Products

Docmost